Shortly after Thanksgiving, I was having issues with the Ping.exe running my CPU usage up to 100% and freezing my computer. I ran my Avira Antivirus and it said it had found a Trojan, and quarantined it. However, after this, I was still having issues with the Ping.exe issue.
I then tried to do a system restore to "undo" these issues, but it told me that it was unable to complete the restore, and left me still having issues. As I was looking for resolutions online, I found PhilliePhan's thread helping out another person with similar issues. He referred him back to a previous thread, and I followed those steps.
http://www.daniweb.com/hardware-and-software/microsoft-windows/viruses-spyware-and-other-nasties/threads/134865
I ran the newest MalwareBytes AntiMalware version previously, and Avira both claimed to find 1 threat, and quarantine it. I can get you a screen shot of the message if it would help. I was still not able to run my system restore function and have it complete successfully. I read another forum that suggested turning off the system restore > rebooting > re-activating system restore. I did that already, however I have not tried it out yet.
I have also lost connectivity on my wireless adapter (however that might not be related)? It is telling me that I am connected to my network, and authenticated however it never assigns an address, and then tells me that I have limited or no connectivity. For this I have tried to reset the wireless adapter, the router, and even checked a few of the forums looking for other suggestions.
I am way over my head here, and getting frustrated. I just had my computer repaired back in April by a guy in my church.
I was hoping someone could take a look thru the files that PhilliePhan requested, and help me out with my issues.
Thanks in advance for any help!
Here are the requested files
GMER One:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-12-04 17:31:56
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3120023A rev.3.33
Running: 0d3kkovl.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\afacyfog.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
GMER Two:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-04 18:42:26
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3120023A rev.3.33
Running: 0d3kkovl.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\afacyfog.sys
---- System - GMER 1.0.15 ----
SSDT F8B57A4C ZwClose
SSDT F8B57A06 ZwCreateKey
SSDT F8B57A56 ZwCreateSection
SSDT F8B579FC ZwCreateThread
SSDT F8B57A0B ZwDeleteKey
SSDT F8B57A15 ZwDeleteValueKey
SSDT F8B57A47 ZwDuplicateObject
SSDT F8B57A1A ZwLoadKey
SSDT F8B579E8 ZwOpenProcess
SSDT F8B579ED ZwOpenThread
SSDT F8B57A24 ZwReplaceKey
SSDT F8B57A1F ZwRestoreKey
SSDT F8B57A5B ZwSetContextThread
SSDT F8B57A10 ZwSetValueKey
SSDT F8B579F7 ZwTerminateProcess
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB25972$\2319490435 0 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996 0 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\bckfg.tmp 803 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\cfg.ini 201 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\keywords 197 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\L 0 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\L\okybosud 162816 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\lsflt7.ver 5176 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U 0 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\00000001.@ 1536 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\80000000.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\80000032.$ 0 bytes
File C:\WINDOWS\$NtUninstallKB25972$\3449333996\U\80000032.@ 98304 bytes
---- EOF - GMER 1.0.15 ----
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27
Run by Owner at 20:29:22 on 2011-12-04
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.95 [GMT -5:00]
.
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Wireless\NT-USB150M Wireless N Client Utility\NWCU.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Owner\Desktop\windows-kb890830-v4.2.exe
c:\6aefb0d242c0c7ff2f3e22\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NWCU] "c:\program files\wireless\nt-usb150m wireless n client utility\NWCU.exe" -nogui
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{058D4BD2-8779-4888-BA4A-BF309078DE48} : DhcpNameServer = 192.168.2.1 192.168.2.1
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\wvpwlq2l.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R? NPF;WinPcap Packet Driver (NPF)
R? WMZuneComm;Zune Windows Mobile Connectivity Service
S? AntiVirSchedulerService;Avira AntiVir Scheduler
S? AntiVirService;Avira AntiVir Guard
S? AR9271;Wireless Network Adapter Service
S? avgio;avgio
S? avgntflt;avgntflt
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
.
=============== Created Last 30 ================
.
2011-12-05 01:28:58 -------- d-----w- C:\6aefb0d242c0c7ff2f3e22
2011-12-04 01:55:10 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2011-12-03 22:45:27 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-12-03 22:45:27 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-03 22:44:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-03 20:02:46 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-03 20:02:11 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-30 18:13:05 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2011-11-30 18:13:05 281104 ----a-w- c:\windows\system32\wpcap.dll
2011-11-30 18:13:05 100880 ----a-w- c:\windows\system32\Packet.dll
2011-11-09 05:08:42 -------- d-----w- c:\documents and settings\owner\local settings\application data\AOL
2011-11-09 05:04:25 -------- d-----w- c:\program files\common files\Software Update Utility
2011-11-09 05:04:24 -------- d-----w- c:\program files\common files\AOL
.
==================== Find3M ====================
.
2011-11-08 01:39:07 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 20:31:58.93 ===============
Attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/18/2011 6:59:13 PM
System Uptime: 12/4/2011 5:03:31 PM (3 hours ago)
.
Motherboard: Dell Computer Corp. | |
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Microprocessor | 3056/533mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 28.217 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Input Device
Device ID: PCI\VEN_1102&DEV_7004&SUBSYS_10031102&REV_00\4&3B1CAF2B&0&11F0
Manufacturer:
Name: PCI Input Device
PNP Device ID: PCI\VEN_1102&DEV_7004&SUBSYS_10031102&REV_00\4&3B1CAF2B&0&11F0
Service:
.
==== System Restore Points ===================
.
RP103: 9/6/2011 12:48:59 PM - System Checkpoint
RP104: 9/7/2011 8:17:20 PM - System Checkpoint
RP105: 9/9/2011 12:29:39 PM - System Checkpoint
RP106: 9/12/2011 3:24:34 PM - System Checkpoint
RP107: 9/14/2011 12:04:30 AM - System Checkpoint
RP108: 9/16/2011 11:59:19 AM - System Checkpoint
RP109: 9/19/2011 9:20:25 PM - System Checkpoint
RP110: 9/21/2011 12:49:20 AM - System Checkpoint
RP111: 9/22/2011 3:10:40 PM - System Checkpoint
RP112: 9/24/2011 2:48:14 PM - System Checkpoint
RP113: 9/27/2011 12:43:00 AM - System Checkpoint
RP114: 9/28/2011 5:15:18 PM - System Checkpoint
RP115: 9/30/2011 1:09:08 PM - System Checkpoint
RP116: 10/12/2011 2:49:03 PM - System Checkpoint
RP117: 10/14/2011 1:08:30 AM - System Checkpoint
RP118: 10/17/2011 3:20:57 PM - System Checkpoint
RP119: 10/19/2011 3:18:38 PM - System Checkpoint
RP120: 10/21/2011 4:48:53 PM - System Checkpoint
RP121: 10/24/2011 4:49:43 PM - System Checkpoint
RP122: 10/25/2011 6:41:31 PM - System Checkpoint
RP123: 10/28/2011 3:07:28 PM - System Checkpoint
RP124: 10/31/2011 1:35:34 PM - System Checkpoint
RP125: 11/1/2011 2:02:13 PM - System Checkpoint
RP126: 11/2/2011 4:23:52 PM - System Checkpoint
RP127: 11/3/2011 4:50:55 PM - System Checkpoint
RP128: 11/7/2011 8:37:54 AM - System Checkpoint
RP129: 11/9/2011 8:56:52 PM - System Checkpoint
RP130: 11/14/2011 12:48:26 PM - System Checkpoint
RP131: 11/15/2011 1:37:31 PM - System Checkpoint
RP132: 11/17/2011 7:58:43 PM - System Checkpoint
RP133: 11/18/2011 11:02:27 PM - System Checkpoint
RP134: 11/21/2011 2:11:05 PM - System Checkpoint
RP135: 11/22/2011 3:49:47 PM - System Checkpoint
RP136: 11/26/2011 9:28:51 PM - no audio !!!
RP137: 11/26/2011 9:29:45 PM - Restore Operation
RP138: 11/26/2011 10:59:59 PM - after problem resolved and scan done
RP139: 11/28/2011 3:15:48 PM - System Checkpoint
RP140: 11/29/2011 7:34:41 PM - System Checkpoint
RP141: 11/30/2011 2:44:52 AM - Restore Operation
RP142: 11/30/2011 2:56:15 AM - after fake antivirus scare
RP143: 11/30/2011 1:34:00 PM - repaired after scare - SRB
RP144: 11/30/2011 9:50:10 PM - Restore Operation
RP145: 11/30/2011 9:53:01 PM - back again i think - srb
RP146: 12/3/2011 3:52:50 PM - System Checkpoint
RP147: 12/3/2011 4:53:27 PM - Restore Operation
RP148: 12/3/2011 5:06:30 PM - Restore Operation
RP149: 12/3/2011 5:10:29 PM - Restore Operation
RP150: 12/3/2011 5:24:41 PM - minus two exe's
RP151: 12/3/2011 5:44:17 PM - Restore Operation
RP152: 12/3/2011 5:56:19 PM - Restore Operation
RP153: 12/3/2011 6:21:49 PM - Restore Operation
RP154: 12/3/2011 9:02:08 PM - Restore Operation
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop 7.0
Adobe Reader X (10.1.0)
Audacity 1.3.13 (Unicode)
Avira AntiVir Personal - Free Antivirus
BCM V.92 56K Modem
CleanUp!
ConvertHelper 2.2
Download Updater (AOL LLC)
Easy CD Creator 5 Basic
Facebook Video Calling 1.0.0.8953
Ghost Recon
Google Talk Plugin
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format 11 SDK (KB973442)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Intel(R) PRO Network Connections Drivers
Java Auto Updater
Java(TM) 6 Update 27
Logitech Vid
Logitech Webcam Software
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft WinUsb 1.0
Mozilla Firefox 8.0 (x86 en-US)
NT-USB150M Wireless N Client Utility
NVIDIA Display Driver
Project64 1.6
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2497640)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
Spybot - Search & Destroy
Tom Clancy's Rainbow Six 3: Raven Shield
Tom Clancy's Splinter Cell
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
UpStage 1.0.2.0
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Mobile Device Updater Component
Windows Tetris 1.01
Windows XP Service Pack 3
Zune
Zune Language Pack (DEU)
Zune Language Pack (ESP)
Zune Language Pack (FRA)
Zune Language Pack (ITA)
Zune Language Pack (NLD)
Zune Language Pack (PTB)
Zune Language Pack (PTG)
.
==== Event Viewer Messages From Past Week ========
.
12/4/2011 5:40:39 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
12/4/2011 4:20:13 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
12/4/2011 4:20:02 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
12/3/2011 9:18:36 PM, error: Service Control Manager [7000] - The MBAMSwissArmy service failed to start due to the following error: The system cannot find the file specified.
12/3/2011 4:52:55 PM, error: Service Control Manager [7003] - The TCP/IP NetBIOS Helper service depends on the following nonexistent service: NetBT
12/3/2011 4:52:55 PM, error: Service Control Manager [7003] - The DHCP Client service depends on the following nonexistent service: NetBT
11/30/2011 9:15:50 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ssmdrv Tcpip
11/30/2011 9:15:50 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
11/30/2011 9:15:50 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/30/2011 9:15:50 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/30/2011 9:15:50 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
11/30/2011 9:15:32 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
11/30/2011 9:15:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
11/30/2011 2:51:32 AM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found.
.
==== End Of File ===========================
MBAM Log:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7622
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/4/2011 8:26:50 PM
mbam-log-2011-12-04 (20-26-50).txt
Scan type: Full scan (C:\|)
Objects scanned: 239653
Time elapsed: 1 hour(s), 43 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)